Junglewise Threat Intelligence

CVE-2026-13987: Google Chrome for Android UI spoofing in Mobile UI

CVE-2026-13987 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for Android could allow a malicious website to misrepresent its identity or security status. By tricking the browser's user interface, an attacker could potentially deceive users into providing sensitive information or performing unintended actions on a fraudulent page. This issue primarily impacts the visual trust indicators users rely on when browsing on mobile devices.

Technical details

A UI spoofing vulnerability exists in the mobile version of Google Chrome for Android. The flaw stems from an incorrect implementation of security UI components, which can be manipulated by a remote attacker using a specially crafted HTML page. By exploiting this, an attacker can bypass visual security indicators or misrepresent the origin of a page to a user. This requires the victim to visit a malicious website. The issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats